Out-of-bounds write in Linux kernel - CVE-2026-74649
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to write out of bounds or disclose sensitive information.
The vulnerability exists due to out-of-bounds write in the OnAuthClient() shared-key authentication handler when processing a malformed WLAN_EID_CHALLENGE element during shared-key authentication. A remote attacker can send a specially crafted wireless authentication frame to write out of bounds or disclose sensitive information.
The issue is reachable over the air before association.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74649
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/2c56ef658ac8c6bca36bc5574715e8f717207c6c
- https://git.kernel.org/stable/c/39ae1033071001af9bb4573ebdbb43bbbe88f749
- https://git.kernel.org/stable/c/4ba402fd47009d20e51dbfc934abb562098ea35b
- https://git.kernel.org/stable/c/4d018e7d7d908bdfcb5ecfa922b1d5cb9ddb3722
- https://git.kernel.org/stable/c/6235b5156b48ed5d1ce3410d8f0b2fd67d30d944
- https://git.kernel.org/stable/c/87c2f073d2aaea041d531b8e579c47570b54b3b7
- https://git.kernel.org/stable/c/a28a4b0592e4a37ea471bc0d308513a93133ce7e